MEDIUM 6.5 GitHub

CVE-2026-48786

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint

### Summary The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not apply the same sanitization. ### Impact An authenticated user with Observer, Observer+, or Technician role (global or team-scoped) could retrieve unmasked team enroll secrets and team agent options by

Affected Products

References

Published: 2026-08-12 · Source: GitHub · Feed updated: 2026-08-12
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-08-12 via GitHub. Affected: go/github.com/fleetdm/fleet/v4 < 4.87.0.
vulnfeed aggregates 10467 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.